SapphireStealer Targets Russians With Fake Legal Docs
ID: 2b9761e4-3c80-598b-83f5-4e98a4c93cdf
STIX ID: report--2b9761e4-3c80-598b-83f5-4e98a4c93cdf
Feed Name: Cyble Blog
CRIL observed a campaign targeting Russian individuals that distributes the open‑source SapphireStealer via a fake Russian government website and likely spam links; the .NET executable masquerades as a PDF, drops lure PDF documents, and stealthily collects browser credentials, Telegram data, FileZilla and SSH files, and desktop files, compressing them into a ZIP and exfiltrating to a C2 (example IP 193.39.185.4). The report includes deobfuscated code behavior, MITRE ATT&CK mappings, IOCs (hashes, domain, URL, IP), and recommended mitigations such as email filtering, AV, MFA and backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
